How to reclaim unused licences

Unused seats are not a procurement problem, they are a lifecycle problem. How to find assigned-but-unused licences, why they accumulate faster than anyone reclaims them, and what a monthly reclaim cycle looks like.

7 min read · Last updated September 2026

This is you if

  • Your seat count grows every quarter and never shrinks
  • Nobody can say which paid accounts were used last month

Unused licences aren't a procurement problem. They're a lifecycle problem that arrives on an invoice. The team that gets the invoice can't fix it, and the team that could fix it never sees the invoice.

Every quarter the seat count goes up. It hardly ever comes down. Somebody joins and gets the full department bundle because deciding took longer than granting. Somebody moves teams and keeps the old tooling because nobody removed it. Somebody leaves, the account gets disabled, and the seat keeps billing. Disabling and unassigning are different actions in most vendors, and only one of them is on the offboarding checklist.

Why the waste is mostly not from leavers

This is the part that surprises people, and it's where you should look first.

Offboarding gets the attention because a departed employee with a live account is a security story. But a company that offboards well still leaks licences, because the two biggest sources are both people who are still employed.

Movers. Somebody changes team and keeps the old role's tooling. That seat is now paid for and unused, and no offboarding process will ever fire for it. This is the same accumulation the role change playbook describes, viewed from the invoice instead of the audit.

Over-provisioning at the joiner stage. Granting the whole bundle is faster than deciding which parts of it a role needs, so on a busy Monday the whole bundle is what gets granted. Nobody comes back in month 3 to check which half went unopened.

Disabled, not unassigned. In a lot of vendors, deactivating a user and releasing their licence are separate operations. Offboarding does the first because that's the one that closes the security gap. The seat keeps billing.

Rank those and the picture inverts: the departure you handled correctly is a smaller line than the promotion you didn't think about.

What it takes to find them

Four things, and the first is the one that stalls.

1. Seat-level billing data per app. Not the total invoice, the count of what you're paying for. Some vendors show this in an admin console, some only on the invoice, some only if you ask your rep. Assemble it once and keep it, because you'll need the same table every month.

2. An activity signal per account. Last login is the floor. Meaningful activity is better where the app exposes it: a document opened, a ticket touched, a query run. The difference matters for apps where people authenticate through SSO daily and never actually use the thing.

3. A window everyone has agreed. 60 days is the common settling point. Write it down, because the argument about whether 30 is too aggressive will otherwise happen every month with a different answer.

4. A path to actually release the seat. Finding the seat's the easy half. Releasing it means an admin action in the app, and in the apps where that's manual, reclaim quietly stops happening after the second month.

Iden's finance view, showing licence spend by application and the seats that are assigned but unused.

Licences assigned against licences used. The gap is the money.

The gap between those two columns is the whole exercise. Everything else on this page is about making the gap visible every month instead of once a year in a renewal panic.

Patterns that break it

  1. The annual sweep. Reclaim runs once a year, before renewal. By then you're negotiating with a year of accumulated waste already spent, and the only lever left is the renewal count.
  2. No owner. IT can see the accounts, finance can see the invoices, and neither can see both. This is why the exercise stalls more often than it fails: nobody's objective contains it.
  3. Reclaiming and re-granting the same seat. Somebody's licence is pulled, they need it 3 weeks later, they ask, it comes back. Do this twice and the team stops trusting the process. The fix is a window long enough that a reclaim is rarely wrong, not a faster approval to get it back.
  4. Counting seats and ignoring tiers. Seat waste is incremental and visible. Tier waste is one wrong line that has been wrong for 2 years, usually because one person needed one Enterprise feature once. It's generally the bigger number.
  5. Treating it as a cost exercise only. An unused paid account is an unused account. The security case and the money case are the same finding, and pages that only make the money case get deprioritised the moment budgets aren't the current fire.

Doing this without a tool

Entirely possible, and worth doing before you decide whether to buy anything, because the number you find is the business case.

  1. Pull the invoice or the seat count for your top 15 apps by spend. Not all of them. The distribution is steep enough that 15 gets you most of the answer.
  2. Export the user list per app with last login where the vendor exposes it.
  3. Join the two by email. A spreadsheet is fine. What you're after is a per-app count of seats billed against accounts active in the last 60 days.
  4. Sort by the gap in currency, not in seats. Twelve unused seats on a $9 tool matters less than 2 on a $140 one, and sorting by count sends you at the wrong app first.
  5. Take the top 3 apps to their owners with the names attached. A list of numbers gets deferred. A list of people gets decided.
  6. Repeat monthly with the same spreadsheet. The first run finds the accumulated backlog. The value is in the second and third runs, which find it before it accumulates.

Step 1 is an afternoon. Step 6 is where it stops, every time. It's nobody's job and it's boring, and both of those are still true in month 4 when the backlog has rebuilt.

What still needs a person

The judgment about periodic work. A finance analyst who uses one tool hard for 8 days at quarter close looks identical to an abandoned account for the other 82. No activity window distinguishes those; somebody who knows the job has to.

The negotiation. Reclaim tells you the right seat count. Taking that to the vendor as a reduction, holding it against a tier downgrade, or trading it for a longer term are all commercial calls. They belong to whoever owns the contract.

And the shared account. A seat used by 4 people through one login is a licence-compliance question before it's a reclaim question, and the answer usually costs money rather than saving it.

Where Iden fits

Steps 2 and 3 above, standing rather than assembled.

Accounts and their activity are already in the system because governing them requires knowing they exist. Licences assigned sit next to licences used, per app, without anyone joining two exports by email. The gap is a number you look at rather than a number you calculate.

The part that matters for reclaim specifically is that the same lifecycle catches the sources. A mover's old tooling comes off with the diff. A leaver's seat is released rather than only disabled, because releasing it is part of what offboarded means in that app. Reclaim stops being a monthly hunt and becomes the residue of the lifecycle running correctly, which is a much smaller number to chase.

Frequently asked questions

A paid seat assigned to an account with no meaningful activity over a defined window, usually 30 or 60 days. The window matters more than the definition: 30 days catches seasonal roles that will come back, 90 days is slow enough that a quarter of waste goes unbilled. Most teams settle on 60 and make exceptions for genuinely periodic work like a year-end close.

Because most waste is not from leavers, it is from movers and from over-provisioning at the joiner stage. Someone changes team and keeps the old tooling. Somebody gets given the whole department bundle on day one because it was faster than deciding. Both leave a paid seat attached to a person who is still at the company, which no offboarding process will ever catch.

Almost never mid-term. What you can do is stop the next invoice being wrong, which means having the usage data before the renewal rather than after it. A reclaim cycle running for 2 quarters before a renewal is worth more than any negotiation tactic.

In most companies nobody's, which is why it does not happen. It sits between IT, who can see the accounts, and finance, who can see the invoices, and neither has the other half. The practical answer is that IT produces the number monthly and finance owns acting on it.

Some vendors expose last-login and nothing else, and some expose nothing. Last-login is a weak signal but it is not a useless one: an account that has not authenticated in 90 days is a safe reclaim in almost every app. Where even that is missing, fall back to asking the team lead once a quarter, and record which apps are in that category so the gap is visible.

It reduces it. An unused paid account is an unused account, which is the same thing an orphaned account is from an attacker's point of view. The licence saving and the attack-surface reduction are the same action counted twice, which is the argument to use when finance and security are in the same room.

It varies too much by stack to promise a number, and any vendor quoting one is quoting an average that is not yours. The honest version is that you can measure it in an afternoon: seats billed against seats used, per app, from your own invoices.

Yes, and it is usually the bigger number. Seat reclaim is visible and incremental; tier waste is one line item that has been wrong for 2 years because somebody needed one Enterprise feature in 2024. Audit tiers at renewal, seats monthly.